PT-2026-26006 · Openclaw · Openclaw

Tdjackey

·

Published

2026-02-21

·

Updated

2026-03-19

·

CVE-2026-22174

CVSS v3.1

6.8

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.22
Description OpenClaw versions before 2026.2.22 inject the x-OpenClaw-relay-token header into Chrome CDP probe traffic on loopback interfaces. This allows local processes to capture the Gateway authentication token. An attacker controlling a loopback port can intercept CDP reachability probes to the /json/version API endpoint and reuse the leaked token as Gateway bearer authentication. The issue affects non-standard shared-user/shared-host installations where an untrusted local user or process can access the loopback relay port. Relevant code paths include src/browser/extension-relay.ts (getChromeExtensionRelayAuthHeaders), src/browser/cdp.helpers.ts (getHeadersWithAuth), and src/browser/chrome.ts (fetchChromeVersion). The issue results in local credential disclosure, potentially leading to further impact depending on the local deployment and enabled Gateway capabilities.
Recommendations Update OpenClaw to version 2026.2.22 or later.

Fix

Authentication Bypass by Spoofing

Missing Authentication

Weakness Enumeration

Related Identifiers

BDU:2026-05034
CVE-2026-22174
GHSA-V3J7-34XH-6G3W

Affected Products

Openclaw